KVKK / GDPR Privacy Notice
Last updated: 2026-09-11
This notice explains, in accordance with Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR), how personal data is processed on the FastDocument platform, for which purposes and on which legal bases, to whom it may be transferred, and the rights you hold in this respect.
1. Identity of the Data Controller and the Dual-Role Explanation
FastDocument is a multi-tenant SaaS platform providing two services to businesses (referred to in this notice as the "Brand"): secure document collection through a brand-specific subdomain, and remote identity verification (KYC). Because of this structure, two distinct roles apply to the processing of personal data, and understanding this distinction matters so that you can direct your rights requests to the correct party.
- End User flows (document upload, identity verification): In these flows your personal data is processed on behalf of, and under the instructions of, the Brand that requested the service from you. The Brand is the data controller and FastDocument acts as the data processor. The sole exception is the biometric security pool described below, for which FastDocument is the data controller.
- Areas where FastDocument is the data controller: data relating to visitors of the fastdocument.net website, administration panel (backoffice) user accounts, account, contract, and billing data of Brand customers, and data held in the biometric security pool.
This notice primarily covers the processing activities FastDocument carries out in its capacity as data controller. Information about End User flows is provided to transparently describe the nature of the processing we perform as a data processor; the primary duty to inform for those flows rests with the relevant Brand, while the duty to inform regarding the biometric security pool rests with FastDocument. The identity and contact details of FastDocument as data controller are available in the contact details at the bottom of this page.
2. Categories of Personal Data Processed
Depending on the service you use, the following categories of personal data are processed on the platform:
- Identity verification (KYC) data: front and back images of the identity document; fields read from the document (full name, Turkish ID number or document number, date of birth, expiry date, nationality, gender); a selfie photograph and a short liveness video.
- Biometric security pool data: a biometric face template (numerical representation) derived from the facial image, one facial photograph, the ID number and (if provided) the username.
- Document collection data: files you submit through the upload form at the Brand’s request, together with any information you declare in the form.
- Contact and verification data: e-mail address and/or telephone number used for one-time password (OTP) verification.
- Transaction security data: technical device and browser signals, IP address, access and activity logs.
- Customer (Brand) account data: authorised user name, business e-mail address, account and billing information. No payment is collected from End Users and no End User payment data is processed.
3. Special Categories of Personal Data and Explicit Consent (KVKK Art. 6)
The facial imagery in the selfie photograph and liveness video captured during the identity verification flow may qualify as biometric data, since it is processed for face matching and anti-spoofing analysis. Biometric data is a special category of personal data under Article 6 of the KVKK, and its processing is based on your explicit consent.
To prevent fraud, and based on your explicit consent, your biometric face template, one photograph of your face, your ID number and (if provided) your username are stored by FastDocument, as data controller, in a security pool for 90 days. In a new verification, the face template is compared with the records in the pool; if there is a match, the Brand you are applying to is shown only that a verification was previously performed, and the data in the pool is not transferred to the Brand or to any third party.
Your explicit consent is obtained through a separate, informed step within the verification flow, before processing begins. If you do not give explicit consent, remote identity verification is not performed; in that case you may contact the relevant Brand regarding any alternative verification methods it offers. You may withdraw your explicit consent at any time; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Purposes of Processing
Your personal data is processed for the following purposes:
- Securely collecting the documents requested by the Brand, running uploaded files through automated security processing (sanitisation/CDR), and delivering them securely to the Brand.
- Performing remote identity verification: live scanning of the identity document, OCR/MRZ reading and checksum validation, face matching against the selfie, liveness checking, and anti-spoofing analysis; presenting the results to the Brand as a decision-support report.
- Fraud prevention: determining whether the face in a new verification matches a record from a previous verification in the biometric security pool.
- Verifying access to the flow and preventing abuse (OTP verification, bot protection, signed single-use links).
- Ensuring platform security, keeping access logs, and maintaining an audit trail.
- Establishing and performing contracts with Brand customers, account management, billing, and compliance with legal obligations.
5. Legal Bases for Processing
Your personal data is processed on the following legal bases set out in Articles 5 and 6 of the KVKK:
- Processing being directly related to the establishment or performance of a contract (KVKK Art. 5/2-c): performance of the service agreement between the Brand and FastDocument; operation of the document collection and verification flows.
- Processing being necessary for compliance with a legal obligation of the data controller (KVKK Art. 5/2-ç): invoicing and accounting records, responding to requests from competent authorities.
- Legitimate interest, provided it does not harm the fundamental rights and freedoms of the data subject (KVKK Art. 5/2-f): ensuring platform security, preventing abuse and fraud, access logging and audit trail.
- Explicit consent (KVKK Art. 6): processing of facial imagery that may qualify as biometric data for identity verification purposes, and its storage in the biometric security pool, is based solely on the explicit consent obtained separately within the flow.
For users within the scope of the GDPR, these bases correspond respectively to Article 6(1)(b) (contract), 6(1)(c) (legal obligation), 6(1)(f) (legitimate interests), and 9(2)(a) (explicit consent) of the GDPR.
6. Method of Collection
Your personal data is collected entirely by electronic means: through the upload forms on the brand-specific subdomain; through live document scanning and selfie/liveness capture via your device’s camera during the verification flow; through the e-mail address or telephone number you provide during OTP verification; and through technical records required for the platform to operate (device/browser signals, access logs). Fields read from the document are obtained through automated OCR/MRZ reading performed on the uploaded images.
7. Transfers of Personal Data and Categories of Recipients
Your personal data may be transferred, only to the extent required by the purposes above, to the following categories of recipients:
- The relevant Brand: document collection outputs and identity verification results are delivered to the Brand that requested the service in its capacity as data controller. If there is a match in the biometric security pool, the Brand you are applying to is informed only that a verification was previously performed; the biometric data, photograph and identity details held in the pool are not transferred.
- Sub-processor service providers: application hosting (Vercel), database (Supabase), object storage (Contabo — EU/Germany data centre), bot protection (Cloudflare Turnstile), Brand payments (Stripe — no payment is collected from End Users), operational notifications (Slack), and e-mail/WhatsApp verification message providers.
- Competent public authorities: where required to comply with legal obligations, upon request and to the extent provided by law.
Data is hosted predominantly in data centres within the European Union. However, due to the infrastructure of the service providers listed above, your personal data may be transferred abroad. International transfers are carried out in accordance with the conditions of Article 9 of the KVKK and, for transfers within the scope of the GDPR, the safeguards of Chapter V (such as appropriate safeguards including standard contractual clauses).
8. Retention Periods
Your personal data is retained for as long as required by the processing purpose and in line with minimum periods prescribed by applicable law:
- Raw images and videos captured during identity verification (document images, selfie, liveness video) are automatically deleted after 7 days by default.
- Data in the biometric security pool (biometric face template, one facial photograph, ID number and, if provided, username): automatically deleted 90 days after the record is created. Deletion of its own record by the Brand does not affect this period; if you withdraw your explicit consent, the data is deleted before the period expires.
- The verification result and the fields extracted from the document are retained for audit purposes.
- Files uploaded through the document collection flow are removed from the platform within a defined period after delivery to the Brand.
- Brand account and billing data is kept for the duration of the contractual relationship and for the statutory retention periods required by commercial and tax legislation.
Retention periods may vary according to the configuration chosen by the Brand acting as data controller (except for the 90-day period of the biometric security pool, which is set by FastDocument); for the specific periods applied to End User data, please refer to the relevant Brand’s privacy notice. Data whose retention period has expired is deleted, destroyed, or anonymised.
9. Data Security Measures, Cookies and Local Storage
FastDocument implements appropriate technical and organisational measures to prevent unlawful processing of and access to personal data and to ensure its safekeeping. These include mandatory HTTPS encryption on all connections, signed single-use upload links, automated security processing (sanitisation/CDR) of uploaded files, access logging, and access control based on the principle of least privilege.
No cookies are used on the platform for advertising, tracking, or analytics purposes. Only technical cookies strictly necessary for the service are present: the administration panel session cookie (administrator users only), Cloudflare Turnstile’s short-lived technical cookie/storage for bot protection, and the technical cookies of the hosting infrastructure (Vercel). Browser local storage (localStorage) is used solely for technical necessities. For details, please see the Cookie Policy.
10. Automated Processing and Decision-Support Nature
In the identity verification flow, OCR/MRZ reading, checksum validation, face matching, liveness checking, and anti-spoofing analysis are performed by automated means. However, the output of this processing is a decision-support report: the final accept or reject decision rests with the relevant Brand, and human review is part of the process. Your right to object to a result arising against you exclusively through analysis by automated systems (KVKK Art. 11/1-g) is reserved; in this context you may request human intervention and review.
11. Your Rights under Article 11 of the KVKK and How to Apply
Under Article 11 of the KVKK, you have the following rights by applying to the data controller:
- To learn whether your personal data is being processed,
- To request information about the processing if your personal data has been processed,
- To learn the purpose of the processing and whether your data is used in line with that purpose,
- To know the third parties to whom your personal data is transferred, in Türkiye or abroad,
- To request correction of your personal data if it is incomplete or inaccurate,
- To request deletion or destruction of your personal data under the conditions set out in Article 7 of the KVKK,
- To request that correction, deletion, and destruction operations be notified to third parties to whom the data has been transferred,
- To object to a result arising against you through analysis of your processed data exclusively by automated systems,
- To claim compensation for damage suffered as a result of unlawful processing of your personal data.
You may submit your requests, in accordance with the Communiqué on the Principles and Procedures for Application to the Data Controller, together with information verifying your identity, to the e-mail address provided in the contact details at the bottom of this page. Your request will be concluded free of charge within thirty days at the latest; where the operation entails an additional cost, the fee set in the tariff determined by the Turkish Personal Data Protection Board may be charged. If your request is rejected, the response is found insufficient, or no response is given in time, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board (KVKK Board).
Important: since the relevant Brand is the data controller for End User flows (document upload, identity verification), you should direct rights requests concerning those flows primarily to the relevant Brand. FastDocument, as data processor, provides reasonable assistance by forwarding such requests to the relevant Brand and supporting the Brand in fulfilling them. Requests concerning the biometric security pool may be submitted directly to FastDocument, as it is the data controller for that processing.
12. GDPR Addendum: Additional Rights for EU Users
If you are located in the European Union and the processing falls within the scope of the GDPR, you have the following rights in addition to those under Article 11 of the KVKK:
- Right to data portability (GDPR Art. 20): to receive data processed by automated means on the basis of consent or contract in a structured, commonly used, machine-readable format, and to have it transmitted to another controller.
- Right to object (GDPR Art. 21): to object, on grounds relating to your particular situation, to processing based on legitimate interests.
- Right to restriction of processing (GDPR Art. 18) and the right to withdraw consent at any time (GDPR Art. 7(3)).
- Right to lodge a complaint with a supervisory authority (GDPR Art. 77): with the data protection supervisory authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
Regarding automated decision-making and profiling (GDPR Art. 22): the automated analyses in the verification process are decision-support in nature; no final decision producing legal effects concerning you, or similarly significantly affecting you, is taken solely by automated processing. The final decision rests with the relevant Brand and human review is part of the process; you also have the right to obtain human intervention, to express your point of view, and to contest the decision.
13. Changes and Contact
This notice may be revised in line with legislative changes or updates to the scope of the service; the current version is always published on this page together with the update date shown at the top. For questions about this notice and for applications under the KVKK/GDPR, please use the contact details at the bottom of this page. For the general framework on the processing of personal data, please also see the Privacy Policy and the Cookie Policy.
Contact & Data Controller Details
You can direct any requests regarding this document to the channels below.
